Threat IntelligenceNew
A built-in Threat Intelligence Platform that ingests live IOC feeds from URLhaus, Feodo Tracker, OpenPhish, AlienVault OTX, and AbuseIPDB — enriching your security data with real-world threat context across every module.
Threat Intelligence
Live IOC feeds, enrichment, and threat lookup
Key capabilities
Live Feed Ingestion
Automatically pulls IOCs from URLhaus, Feodo Tracker botnet C2 IPs, OpenPhish, AlienVault OTX, and AbuseIPDB on a configurable schedule.
IOC Database
Maintains a searchable, filterable database of all active Indicators of Compromise — IPs, domains, URLs, and file hashes — per client.
Real-Time Lookup
Instantly check any IP, domain, URL, or hash against your live IOC database from anywhere in the platform.
Cross-Module Enrichment
TIP match badges appear automatically in HakScout, Investigations, and other modules — surfacing threat context where you need it.
Manual IOC Entry
Add custom IOCs from your own threat intelligence sources, incident findings, or vendor advisories.
IOC Dashboard
Visual dashboard showing IOC counts by type and severity, feed sync status, and recently added indicators.
Why Threat Intelligence?
- URLhaus, Feodo Tracker, OpenPhish — free feeds, no key required
- AlienVault OTX and AbuseIPDB with API key
- IOC match badges surfaced across HakScout, Investigations and more
- Per-client IOC database — no cross-tenant data mixing
- MERGE upserts keep IOC data current without duplication
Threat Intelligence is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.
Related modules
See Threat Intelligence in action
Request a personalised demo and we'll show you exactly how Threat Intelligence works within your environment.